Desk live·
ForensicPost
Cloud/Exploitation/File 25-0424

Attackers Uploaded Webshells to Internet-Facing SAP NetWeaver Systems

Attackers uploaded JSP webshells to publicly accessible directories on SAP NetWeaver systems in April 2025. The system that runs the business was reachable from outside it.

Constructed geometry · not a chart of case data
TargetSAP NetWeaver estates
ActorUnattributed
S. Rosler11 min readConfidence: medium2 sources reviewed

Security researchers investigating multiple customer incidents in April 2025 found unauthorised file uploads and execution on SAP NetWeaver systems, with attackers placing JSP webshells in publicly accessible directories.

ERP Is Where Everything Already Is

An enterprise resource planning system holds the general ledger, the supplier master, the purchase orders, the payroll and the inventory positions. It is not a system that holds a copy of something — it is the system of record.

Access to it does not require lateral movement to become valuable. Payments can be redirected, suppliers created, inventory positions read. This desk filed ten months inside an unwatched ERP at 26-0620; this file is the same class of asset, reached through an internet-facing upload path.

A Webshell Is The Least Sophisticated Thing In This Database

It is a file that accepts commands over the web. The technique is decades old, requires no exploit development, and works whenever an attacker can write to a directory the web server will execute from.

That such a technique succeeds against a business-critical platform is the finding. The failure was architectural — a writable, executable, externally reachable path — rather than a matter of adversary capability.

And ERP Patching Is The Hardest Patching There Is

These systems are heavily customised, integrated with everything, and validated against business processes. An update is a project with testing cycles, not an overnight change, and downtime means the company cannot invoice or ship.

The result is estates that run behind by design, on the reasoning that they are internal systems. This file records what happens when that assumption stops being true. Graded medium: the technique and platform are consistently reported, the affected organisations are not named and the scale is not established.

How we reported this

Compiled from published vendor research, listed below. Affected organisations are not named and the number of incidents is not established. Corrections: corrections@forensicpost.com.

Sources
  1. Lessons from 2025: zero-day exploitation shaping 2026Outpost24
  2. Top zero-day vulnerabilities exploited in the wild in 2025Cybersecurity News
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary